clause.watch Contracts Recent changes Start monitoring

Monitored company

Tropicapp

clause.watch tracks 1 legal document published by Tropicapp, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

12,402 characters · Read the original

Privacy Policy Overview

Last updated: October 20, 2023

Company: Tropic Technologies, Inc. (“Tropic”)

This policy covers information collected through the Tropic website, software platform, and related electronic communications. It does not generally cover offline information, other Tropic websites/apps, or third-party services and authentication systems.

1. Data Collection & Usage

Information collected

Tropic may collect:

  • Personal information: Name, email address, account details, correspondence, survey responses, and information submitted through forms.
  • Company information: Company name, size, structure, and number of employees.
  • Technical and usage information: IP address, geographic location, browser and operating system, device information, traffic and log data, pages/resources accessed, and usage patterns.
  • User Contributions: Information you post, transmit, or share with other users or third parties through the platform.

Information is collected directly from you, automatically through cookies and similar technologies, and potentially from third parties.

How it is used

Tropic may use information to:

  • Provide, operate, personalize, and improve the platform;
  • Respond to requests and provide requested products or services;
  • Manage accounts and send service notices;
  • Notify users of platform or service changes;
  • Analyze usage and audience patterns;
  • Send promotional communications, including potentially promoting third-party products or services; and
  • Carry out purposes disclosed at collection or with your consent.

The policy permits broad use for purposes described when information is provided and “any other purpose with your consent.”

2. User Rights and Choices

Users may:

  • Review and change certain personal information through their account profile;
  • Email privacy@tropicapp.io to request access, correction, or deletion;
  • Opt out of promotional email communications by contacting Tropic;
  • Control cookies through browser settings.

Important limitations:

  • Tropic states it cannot delete personal information without also deleting the user account.
  • Requests may be refused where changes would violate law or make information inaccurate.
  • Deleted User Contributions may remain in caches, archives, or copies held by other users.
  • The policy does not expressly describe rights such as data portability, objection, restriction, or jurisdiction-specific rights under laws such as GDPR or CCPA.
  • Disabling cookies may make portions of the platform unavailable or malfunction.

3. Third-Party Sharing

Tropic may share personal information with:

  • Employees, contractors, service providers, and other business-support vendors;
  • Parties involved in providing the service or fulfilling your request;
  • Buyers or successors in a merger, restructuring, asset sale, bankruptcy, or similar transaction;
  • Courts, regulators, government authorities, or law enforcement where legally required;
  • Parties where disclosure is needed to protect Tropic, users, or others;
  • Software vendors when a buyer gives permission or instructs Tropic to facilitate a transaction; and
  • Prospective buyers, comparison vendors, or other transaction participants when the user is a software vendor.

Aggregated and de-identified information may be disclosed without restriction. Third-party advertising providers may independently collect information, and Tropic does not control their practices. A list of subprocessors is available at tropicapp.io/subprocessors.

Google single sign-on data is subject to Google’s API Services User Data Policy and Limited Use requirements.

4. AI/ML Training

The policy does not state whether user data, User Contributions, or platform data is used to train artificial intelligence or machine-learning models. Users should seek clarification from Tropic or review the applicable master services agreement, data-processing terms, or data management policy before submitting sensitive information.

5. Key User Obligations and Risks

Users are responsible for:

  • Keeping passwords confidential and not sharing them;
  • Ensuring information provided is accurate;
  • Using the platform and User Contributions consistently with the master services agreement and acceptable use policy;
  • Understanding that shared User Contributions may be viewed, copied, or redistributed by others; and
  • Maintaining a current, deliverable email address for policy-change notices.

Tropic warns that no security system is impenetrable and that internet transmission occurs at the user’s risk.

6. Liability and Disputes

This policy contains no detailed limitation of liability, indemnity, governing-law, arbitration, or dispute-resolution terms. It refers users to the master services agreement and acceptable use policy, which may contain those provisions. The policy does disclaim responsibility for security breaches caused by circumvention of platform safeguards and does not guarantee complete security.

7. Policy Changes

Tropic may change the policy by:

  • Posting the revised policy on the same page;
  • Showing an update notice upon platform login; or
  • Posting notice on the website home page.

Continued use after changes constitutes acceptance. Users are responsible for checking the policy periodically and maintaining a current email address.

Change history

2026-08-26 · Privacy Policy

shrank 3.1% · Observed by clause.watch

Summary

The diff only states that approximately 51 words were removed from the document. The actual deleted language is not provided.

AI Training and Data Use
  • It is not possible to determine whether the removed text addressed:
  • Use of customer data to train, fine-tune, or improve AI models;
  • Whether customer data may be used for general-purpose or third-party model training;
  • De-identification, anonymization, or aggregation of customer data;
  • Customer consent or opt-out rights;
  • Restrictions on using prompts, outputs, files, or usage metadata for training;
  • Retention, deletion, or human-review practices relating to AI systems.
  • If the deleted language contained restrictions on AI training or data use, its removal could expand the provider’s rights to use customer data or create ambiguity about those rights.
Other Potential Legal Impact

Because the deleted wording is unavailable, it is also impossible to assess whether the changes affect:

  • Confidentiality obligations;
  • Intellectual-property ownership or licensing;
  • Data-protection compliance;
  • Security obligations;
  • Data retention or deletion;
  • Liability, indemnification, or audit rights;
  • Customer notice or consent requirements.
Risk Assessment

The change should be treated as indeterminate but potentially material, particularly if the document concerns software, cloud services, or AI-enabled products. A deletion of only 51 words can materially alter a limitation, exception, consent requirement, or data-use authorization.

Recommended Next Step

Obtain the actual redline or the deleted wording before accepting the amendment. Compare the removed text with the surrounding provisions and specifically confirm that the contract clearly states:

1. Whether customer data may be used to train or improve AI models;

2. Whether such use requires customer consent;

3. Whether customer data is excluded from general or third-party model training;

4. How prompts, outputs, and usage metadata are handled; and

5. What deletion, retention, confidentiality, and security protections apply.

2026-08-25 · Privacy Policy

grew 3.2% · Observed by clause.watch

Summary of Important Changes

Overall assessment

Most changes are editorial or formatting-related, including replacing curly quotation marks and apostrophes with straight ones, correcting spacing, and adding punctuation. These changes do not appear to alter the parties’ substantive rights or obligations.

Data collection and use

  • The policy continues to state that Tropic may collect:
  • Personal information, such as names and email addresses;
  • Company information, such as company size and number of employees; and
  • Non-identifying information about users.
  • The listed collection methods remain substantially unchanged, including information provided directly by users, collected automatically through use of the platform, and obtained from third parties.
  • The policy continues to permit use of information for purposes disclosed in the policy, with consent, and for other stated business and legal purposes.

AI model training

  • No express change regarding use of customer data to train artificial intelligence or machine-learning models was identified.
  • The revised text does not add or remove language expressly authorizing Tropic to:
  • Train AI or machine-learning models using customer data;
  • Use customer content, prompts, documents, or other user contributions for model development;
  • Create aggregated or de-identified datasets for AI training; or
  • Permit third-party AI providers to use customer data for training.
  • However, the policy’s general-purpose data-use language may still be broad enough to permit uses described elsewhere in the policy, other agreements, or disclosed with consent. Customers should review the applicable platform terms, data-processing agreement, and product-specific AI terms for any separate AI provisions.

Google SSO

  • The revised wording more clearly references Google’s Limited Use Policy and “Tropic Google SSO’s use and transfer” of information received from Google.
  • This appears primarily to clarify or repair the existing Google SSO disclosure rather than create a clearly new permission. Nevertheless, users should confirm what Google account information Tropic receives and how it is used.

Data management and security

  • The policy now provides a specific email address—privacy@tropicapp.io—for questions about Tropic’s data-management policy.
  • This improves contact clarity but does not appear to add a new security commitment or materially change Tropic’s security obligations.

Third-party disclosures and notices

  • The policy continues to reference Tropic’s subprocessors and now more clearly provides a link to the candidate privacy notice.
  • The references to subprocessors and candidate information may increase transparency, but the excerpt does not change the scope of permitted disclosures or impose customer approval rights.

Marketing

  • The existing opt-out process for promotional emails remains. No material change to marketing permissions was identified.

2026-08-23 · Privacy Policy

shrank 3.1% · Observed by clause.watch

Summary of Important Changes

Overall Assessment

The diff appears to make primarily formatting, punctuation, quotation-mark, and webpage-text cleanup changes. It does not appear to add or remove substantive data-use rights, security commitments, or user rights.

Changes Identified

1. No apparent change to AI-model training rights
  • The diff contains no express reference to artificial intelligence, machine learning, model training, model improvement, generative AI, or use of customer data to train models.
  • No language appears to have been added authorizing Tropic or its service providers to use customer data, User Contributions, or personal information for AI training.
  • Likewise, the diff does not add a prohibition or limitation on such use.
  • Any AI-training terms that may exist elsewhere in the full Privacy Policy, Terms of Service, Data Processing Addendum, or product documentation are not shown in this diff and cannot be assessed here.
2. Terminology and punctuation standardized

The revision changes straight quotation marks and apostrophes to typographic quotation marks, including references to:

  • “Tropic”
  • “Website”
  • “Policy”
  • “personal information”
  • “posted”
  • “User Contributions”
  • “Tropic’s”
  • “Google’s”

These edits do not appear to change the legal meaning.

3. Data-collection descriptions reformatted

Several list items and sentence breaks were corrected, including descriptions of information collected:

  • Through the Tropic Platform
  • Through electronic messages
  • Through third-party websites, applications, authentication procedures, and advertising
  • Directly from users or automatically through platform use

The apparent changes are grammatical and formatting-related rather than substantive.

4. Google SSO language

The reference to Google’s Limited Use Policy and “Tropic Google SSO’s use and transfer” was reformatted. The diff does not show any change to:

  • The categories of Google data collected
  • How Google data may be used or transferred
  • Any restrictions imposed by Google’s Limited Use Policy
5. Data management and security sections

The reference to Tropic’s data management policy and the “Data Security” heading was cleaned up. No new security obligation, standard, warranty, or breach-notification commitment is visible.

6. Subprocessor and candidate privacy links

The subprocessor and candidate privacy notice references were cleaned up, and apparent promotional footer text was removed. This may improve presentation but does not appear to change Tropic’s authority to use subprocessors.

Key Risk Takeaway

The diff does not create an identifiable new legal risk or new AI-training permission. However, because it does not address AI use, customers should review the complete agreement set for separate provisions allowing use of customer data for analytics, service improvement, de-identification, or AI/model training.

2026-08-22 · Privacy Policy

grew 3.2% · Observed by clause.watch

Summary

The provided diff does not include the actual contractual language that was added, deleted, or replaced. It only states:

> “Added approximately 51 words to the document”

Accordingly, no specific legal changes or risks can be identified from the information provided.

AI Training and Customer Data

The diff does not reveal whether the added text changes:

  • Whether customer data may be used to train, fine-tune, or improve AI models;
  • Whether customer prompts, inputs, outputs, files, or usage data are used for model development;
  • Whether training is conducted by the provider or third-party service providers;
  • Whether the customer can opt out of AI training or must pay for an opt-out;
  • Whether data is anonymized, aggregated, or de-identified before use;
  • Whether the provider obtains ownership or a broad license to use customer data;
  • How long training-related data is retained; or
  • Whether customer data may be transferred across jurisdictions.

Risk Assessment

Because the actual 51 added words are missing, it is not possible to determine whether they:

  • Expand the provider’s rights to use customer data;
  • Create a new license or ownership claim;
  • Permit disclosure to affiliates or vendors;
  • Reduce confidentiality protections;
  • Change data-retention or deletion obligations;
  • Limit the customer’s ability to object to AI-related processing; or
  • Introduce compliance, privacy, or intellectual-property risks.

Information Needed

To perform a meaningful legal review, provide the exact text of the additions and any surrounding provisions, particularly sections addressing:

  • Customer data and content;
  • Confidentiality;
  • Privacy and data processing;
  • AI, machine learning, or model training;
  • Intellectual-property rights; and
  • Data retention and deletion.

2026-08-22 · Privacy Policy

shrank 3.1% · Observed by clause.watch

Summary of Important Changes

1. No apparent changes to AI-model training or data-use rights
  • The diff does not add, remove, or modify language expressly addressing:
  • Training, fine-tuning, or improving AI models;
  • Use of customer data, User Contributions, prompts, outputs, or platform content for AI development;
  • Whether data is de-identified before AI use;
  • Customer opt-out rights or consent requirements for AI training; or
  • Restrictions on using confidential or personal information in AI systems.
  • References to data collection, User Contributions, consent, Google SSO, third-party advertising, and data management appear substantively unchanged.
  • Accordingly, based solely on this diff, there is no identifiable change in Tropic’s authorization to use customer data for AI training. Any such rights may still exist in unchanged portions of the policy or in other contractual documents.
2. Mostly editorial and formatting revisions

The following changes appear non-substantive:

  • Standardization of quotation marks from straight quotes to typographic curly quotes.
  • Correction of spacing and punctuation in numbered lists.
  • Minor grammatical and typographical cleanup, including possessives such as “Tropic’s” and “third parties’.”
  • Formatting cleanup around headings, including “Data Security,” “Contact Information,” and “Subprocessors.”
  • Removal of an apparent marketing footer promoting Tropic’s savings, efficiency, and demo request. This does not appear to change privacy rights or obligations.
3. Third-party and Google SSO references
  • The wording and presentation of the reference to Google’s Limited Use Policy and Tropic’s Google SSO remain substantively the same.
  • No new permissions or restrictions concerning Google-provided data are visible in the diff.
  • The policy continues to reference third-party collection and use of information, including interest-based advertising. The edits do not appear to expand or narrow those rights.
4. Links and notices
  • The Subprocessors page and candidate privacy notice links appear to have been retained, with formatting changes only.
  • There is no visible change to the policy’s treatment of subprocessors, data transfers, or disclosures during corporate transactions.

Risk Assessment

  • AI-training risk from this diff: Low or indeterminate. No AI-training language is changed, but the diff does not establish what the full policy permits.
  • Legal-impact risk: Low. The changes appear primarily editorial, formatting-related, or marketing-content-related.
  • Customers should review the complete current policy, terms of service, data-processing agreement, and any product-specific AI terms to determine whether customer data may be used to train or improve AI models.

Between 2024-04-23 and 2024-08-27 · Privacy Policy

shrank 4.2% · Reconstructed from Internet Archive captures

Diff Analysis

Summary

The diff states only that approximately 51 words were removed from the document. The actual deleted language is not provided.

Important Legal Changes

Because the specific text is unavailable, it is not possible to determine:

  • Which contractual rights or obligations were removed.
  • Whether liability, indemnification, confidentiality, privacy, security, or termination provisions changed.
  • Whether any customer protections were weakened.
  • Whether obligations relating to data ownership, permitted data use, or service-provider access were narrowed or eliminated.

AI Model Training and Customer Data

No conclusion can be reached about AI training practices from the information provided. The deleted 51 words could potentially have affected provisions concerning:

  • Use of customer data to train, fine-tune, evaluate, or improve AI models.
  • Whether customer content is used for product development or service improvement.
  • Whether data is anonymized, aggregated, or de-identified before such use.
  • Whether the customer may opt out of AI training or other secondary uses.
  • Whether human reviewers or third-party AI providers may access customer data.
  • Ownership of model inputs, outputs, derivatives, or improvements.
  • Retention and deletion of data used in AI systems.

Risk Assessment

The principal risk is that the deletion may remove a restriction, disclosure, consent requirement, or customer opt-out right. However, the direction and significance of the change cannot be assessed without the actual deleted wording and the surrounding provisions.

Information Needed

To perform a substantive legal analysis, provide:

1. The 51 deleted words, preferably in their original location; and

2. Any surrounding section or paragraph needed to interpret them.

Without that text, there is no reliable basis to identify specific legal or AI-data risks.

Between 2023-06-26 and 2024-04-23 · Privacy Policy

grew 3.1% · Reconstructed from Internet Archive captures

Summary of Important Changes

1. No Express Change to AI-Model Training

  • The diff does **not add or remove any provision expressly authorizing Tropic to use customer data, personal information, User Contributions, or platform content to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.
  • It also does not add an express prohibition on such use.
  • Accordingly, the policy remains potentially ambiguous if Tropic’s broader rights to use information for “any other purpose disclosed by us,” service operations, analytics, or product improvement appear elsewhere in the full policy. The complete policy and any terms of service, data-processing agreement, or AI-specific terms should be reviewed for training-related language.

2. Clarification of Information Sources and Categories

The revisions mainly correct formatting and punctuation while preserving the apparent substance of the provisions describing:

  • Information collected through the Tropic Platform and electronic communications.
  • Information collected through interactions with third-party websites, applications, advertising, and authentication procedures.
  • Personal information, company-identifying information, and non-identifying information.
  • Information supplied directly by users or collected automatically through platform use.
  • User Contributions posted on or transmitted to other users or third parties.

Risk: The continued reference to User Contributions being transmitted to others may permit broad sharing of customer-submitted content, depending on the operative provisions that follow. The diff does not clarify whether confidential business data included in User Contributions is excluded from sharing or secondary use.

3. Google SSO Language

  • “Google’s Limited Use Policy” and “Tropic Google SSO’s” language is reformatted but not materially changed.
  • No new Google-data permission or restriction is apparent in this diff.

4. Data Sharing, Marketing, and Corporate Transactions

The revisions preserve provisions concerning:

  • Transfer of personal information in a merger, reorganization, bankruptcy, liquidation, or sale of assets.
  • Promotional use of email addresses by Tropic or third parties, with an opt-out available by emailing privacy@tropicapp.io.
  • The fact that Tropic does not control third parties’ use of information for interest-based advertising.

Risks: Personal information may be transferred to an acquiring entity, and third-party advertising practices may remain outside Tropic’s control. The opt-out process appears manual rather than an automated preference mechanism.

5. Data Management, Security, and Contact Information

  • A broken or incomplete reference to Tropic’s data management policy is replaced with a statement directing questions to privacy@tropicapp.io.
  • The contact-information and subprocessors sections are reorganized and clarified.
  • A link to the candidate privacy notice remains included.

6. Website Content Inserted

Marketing copy—“Drive savings and efficiency…” and “Schedule a Demo”—has been appended. This appears unrelated to privacy rights or data use but may indicate website-content contamination or an improperly merged document.

Overall assessment: The changes are predominantly editorial and structural. No clear substantive change to AI training rights is shown.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free